
Source Code Management Attack Toolkit - SCMKitは、SCMシステムを攻撃するために使用できるツールキットです。SCMKitを使用すると、使用するSCMシステムと攻撃モジュールを指定し、各SCMシステムへの有効な認証情報(ユーザー名/パスワードまたはAPIキー)を指定できます。現在、SCMKitがサポートしているSCMシステムは、GitHub Enterprise、GitLab Enterprise、Bitbucket Serverです。サポートされている攻撃モジュールには、偵察(reconnaissance)、権限昇格(privilege escalation)、永続化(persistence)が含まれます。SCMKitはモジュール式のアプローチで構築されているため、今後、情報セキュリティコミュニティによって新しいモジュールやSCMシステムを追加できます。
このプロジェクトでは、以下のサードパーティライブラリを使用しています。
| ライブラリ | URL | ライセンス |
|---|---|---|
| Octokit | https://github.com/octokit/octokit.net | MIT License |
| Fody | https://github.com/Fody/Fody | MIT License |
| GitLabApiClient | https://github.com/nmklotas/GitLabApiClient | MIT License |
| Newtonsoft.Json | https://github.com/JamesNK/Newtonsoft.Json | MIT License |
プロジェクトを自分でコンパイルするために、Visual Studioをセットアップするには以下の手順を実行します。これには、NuGetパッケージマネージャーからインストールできる.NETライブラリが必要です。
https://api.nuget.org/v3/index.json でパッケージソースを追加します。Install-Package Costura.Fody -Version 3.3.3Install-Package OctokitInstall-Package GitLabApiClientInstall-Package Newtonsoft.Json以下の表は、各モジュールがサポートされている場所を示しています。
| 攻撃シナリオ | モジュール | 管理者が必要か? | GitHub Enterprise | GitLab Enterprise | Bitbucket Server |
|---|---|---|---|---|---|
| 偵察 | listrepo | いいえ | X | X | X |
| 偵察 | searchrepo | いいえ | X | X | X |
| 偵察 | searchcode | いいえ | X | X | X |
| 偵察 | searchfile | いいえ | X | X | X |
| 偵察 | listsnippet | いいえ | X | ||
| 偵察 | listrunner | いいえ | X | ||
| 偵察 | listgist | いいえ | X | ||
| 偵察 | listorg | いいえ | X | ||
| 偵察 | privs | いいえ | X | X | |
| 偵察 | protection | いいえ | X | ||
| 永続化 | listsshkey | いいえ | X | X | X |
| 永続化 | removesshkey | いいえ | X | X | X |
| 永続化 | createsshkey | いいえ | X | X | X |
| 永続化 | listpat | いいえ | X | X | |
| 永続化 | removepat | いいえ | X | X | |
| 永続化 | createpat | はい(GitLab Enterpriseのみ) | X | X | |
| 権限昇格 | addadmin | はい | X | X | X |
| 権限昇格 | removeadmin | はい | X | X | X |
| 偵察 | adminstats | はい | X |
特定のSCMシステムで使用されているリポジトリを発見する
listrepoモジュールに、関連する認証情報とURLを指定します。これにより、リポジトリ名とURLが出力されます。
これにより、ユーザーが表示できるすべてのリポジトリが一覧表示されます。
SCMKit.exe -s github -m listrepo -c userName:password -u https://github.something.local
SCMKit.exe -s github -m listrepo -c apiKey -u https://github.something.local
これにより、ユーザーが表示できるすべてのリポジトリが一覧表示されます。
SCMKit.exe -s gitlab -m listrepo -c userName:password -u https://gitlab.something.local
SCMKit.exe -s gitlab -m listrepo -c apiKey -u https://gitlab.something.local
これにより、ユーザーが表示できるすべてのリポジトリが一覧表示されます。
SCMKit.exe -s bitbucket -m listrepo -c userName:password -u https://bitbucket.something.local
SCMKit.exe -s bitbucket -m listrepo -c apiKey -u https://bitbucket.something.local
C:>SCMKit.exe -s gitlab -m listrepo -c username:password -u https://gitlab.hogwarts.local
================================================== Module: listrepo System: gitlab Auth Type: Username/Password Options: Target URL: https://gitlab.hogwarts.local
Name | Visibility | URL
MaraudersMap | Private | https://gitlab.hogwarts.local/hpotter/maraudersmap
testingStuff | Internal | https://gitlab.hogwarts.local/adumbledore/testingstuff
Spellbook | Internal | https://gitlab.hogwarts.local/hpotter/spellbook
findShortestPathToGryffindorSword | Internal | https://gitlab.hogwarts.local/hpotter/findShortestPathToGryffindorSword
charms | Public | https://gitlab.hogwarts.local/hgranger/charms
Secret-Spells | Internal | https://gitlab.hogwarts.local/adumbledore/secret-spells
Monitoring | Internal | https://gitlab.hogwarts.local/gitlab-instance-10590c85/Monitoring
### リポジトリの検索
#### 使用例
> *特定のSCMシステム内のリポジトリ名でリポジトリを検索します。*
#### 構文
`searchrepo` モジュールと検索条件を `-o` コマンドラインスイッチで指定し、関連する認証情報とURLを併せて指定します。これにより、一致するリポジトリ名とURLが出力されます。
##### GitHub Enterprise
GitHub のリポジトリ検索は「部分一致」検索であり、入力した文字列は、その検索語を名前に含むリポジトリを検索します。
`SCMKit.exe -s github -m searchrepo -c userName:password -u https://github.something.local -o "some search term"`
`SCMKit.exe -s github -m searchrepo -c apikey -u https://github.something.local -o "some search term"`
##### GitLab Enterprise
GitLab のリポジトリ検索は「部分一致」検索であり、入力した文字列は、その検索語を名前に含むリポジトリを検索します。
`SCMKit.exe -s gitlab -m searchrepo -c userName:password -u https://gitlab.something.local -o "some search term"`
`SCMKit.exe -s gitlab -m searchrepo -c apikey -u https://gitlab.something.local -o "some search term"`
##### Bitbucket Server
Bitbucket のリポジトリ検索は「前方一致」検索であり、入力した文字列は、その検索語で始まる名前のリポジトリを検索します。